This notice is part of the Cutvey Privacy Policy. It explains the cookies and similar technologies Cutvey LLC uses, by category and purpose, across our web app, our marketing and product websites, our native apps and our email.
We have kept this short because there is very little to report. Cutvey runs no advertising cookies, no third-party analytics cookies and no cross-site tracking, anywhere. That is a product decision, not a temporary state.
Strictly necessary cookies only. Without them the app cannot sign you in or keep you safe.
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| Session cookie | Keeps you signed in to your workspace. Signed, HTTP-only, and revocable from Settings | Strictly necessary, first party | Until you sign out, or the session expires |
| Sign-in and device cookie | Remembers a device you marked as trusted, so you are not asked for a code every time | Strictly necessary, first party | Until you revoke the device |
| Security and anti-abuse cookie | Cross-site request forgery protection and rate limiting | Strictly necessary, first party | Session, or short-lived |
| Preference storage | Remembers a choice you made in the app, such as the theme you picked or the view you last used. Kept in your browser's local storage, not sent to our servers. We store it only because you chose it, and storing it is the only way to give you what you asked for | Strictly necessary, first party | Until you clear your browser data |
These are strictly necessary to deliver the service you asked for. Under the EU ePrivacy rules and the UK Privacy and Electronic Communications Regulations they do not require consent, which is why you do not see a cookie consent banner in the app today.
We class nothing as strictly necessary that we would not defend as strictly necessary. Everything above is either what signs you in, what keeps the app safe, or what remembers a choice you actively made. If we ever store or read anything on your device for another reason, including measurement, we will ask you first and give you a way to change your answer.
Our public websites set no analytics cookies, no advertising cookies and no third-party tracking of any kind. We do not use Google Analytics, Meta pixels, LinkedIn Insight, TikTok pixels or anything comparable.
The only cookies you may meet come from the infrastructure that keeps the sites up and keeps bots off our forms:
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| Bot-protection token | Cloudflare, Inc. (Turnstile), on our behalf | Confirms that a human, not a bot, is submitting a contact, support or lead form. Cloudflare states that Turnstile does not use this data for advertising and does not track users across sites. We do not receive an advertising profile or a cross-site identifier from it, and we would not use one | Minutes, tied to the form submission |
Infrastructure cookie (for example __cf_bm) | Cloudflare, Inc. | Tells human traffic from automated traffic so the site stays available. Strictly necessary for security | Up to 30 minutes |
Lead forms in a studio's client portal. A studio's own lead-capture form, served through Cutvey, is protected the same way, using that studio's own configured keys. The studio is the controller of what the form collects.
This section applies to every Cutvey native application, current and future. The Privacy Policy's product table lists them.
Native apps do not use cookies. They store what they need on your device and, where you turn it on, in your own iCloud. In practice what an app keeps on the device is: your settings, your own content, a sign-in token if you signed in, a record of the analytics answer you gave, and a cache of what you last worked on. None of it is shared with anyone else, and deleting the app removes it from the device. Apps contain no advertising SDKs, no attribution SDKs and no cross-site or cross-app tracking technology. Where an app includes a component from a service provider to send us crash reports, that provider is on our subprocessor list and may use the reports only to provide that service to us.
Usage data and crash reports in the apps follow section 8 of the Privacy Policy. Optional usage data and crash reports are on by default where the law allows a default. In the European Economic Area, the United Kingdom, Switzerland, and anywhere else whose law requires your agreement before an app reads or stores this kind of information on your device, every app asks you on first run and collects nothing until you agree. Wherever you are, you can change the answer at any time in the App's Settings. Because there is no advertising or attribution technology in any app, you do not see an App Tracking Transparency prompt. The permission we ask for is about improving our own software, not about following you anywhere else.
Our own email to you. Sign-in codes, receipts, invoices, notifications and security alerts record only delivery and bounce events, because we need to know the message arrived. They carry no tracking pixel.
Our product announcements do record opens and link clicks, so we can tell whether an announcement was worth sending. Measuring an open means loading a small image from our servers, which counts as access to your device under European and UK rules. So we ask for your agreement to that measurement when you subscribe, if you are in the European Economic Area, the United Kingdom or Switzerland. We do not measure opens for anyone who has not agreed. To withdraw, use the preference link in any announcement, or email [email protected]. We record your answer against your email address and apply it to every later message. Every announcement also carries a one-click unsubscribe.
Email a studio sends through Cutvey. A proposal, invoice, call sheet or gallery link that a studio sends to its own client can carry a small tracking image and click-tracked links, so the studio can tell whether the client opened it. The studio decides whether to use tracking and on whom. Our Terms require the studio to disclose it to recipients where its law requires, and to honor a recipient who asks to be emailed without tracking. We build and host the measurement, we secure the data, and we provide the off switch. Every workspace can turn tracking off for all of its outgoing mail in Settings. The engagement data stays in the studio's workspace and we never use it for our own marketing.
If you received such an email and do not want the open counted, most email clients can block remote images, which stops the image from loading. Blocking images does not affect link clicks: if you click a link in the message, the sender can still see that you did. To stop it entirely, ask the studio that sent it.
You can delete or block cookies in your browser settings. Blocking the strictly necessary cookies in section 1 stops you from signing in to the app, which is the whole of what they do.
Because we set nothing beyond strictly necessary on the web, there is no consent preference for you to manage there and no "reject non-essential cookies" button to press. Our native apps are different: where the law requires it they ask you on first run about usage data and crash reporting, because that involves reading information from your device, and wherever you are you control the answer in the App's Settings. If the web app ever needs the same question asked, we will ask it there too.
We update this notice whenever the technologies we use change, and the "Last updated" date above tells you when. Material changes are notified as described in section 20 of the Privacy Policy. When this notice changes, the version it replaces will be kept at https://cutvey.com/legal/archive.
Questions: [email protected].